Security Engineer - SOC

Tallinn

Applications have closed

Wise

160+ countries, 40 currencies, one account. Save when you send, spend and manage your money internationally.

View company page

Wise is one the fastest growing companies in Europe and we’re on a mission: to make money without borders the new normal. We’ve got 10 million customers across the globe and we’re growing. Fast.

Current banking systems don’t let us send, spend or receive money across borders easily. Or quickly. Or cheaply.

So, we’re building a new one.

And, we’re looking for a Security Engineer with focus on SOC to join our Security Operations team in London, who is responsible for the global security features of the Wise products.  

For our customers, using Wise should feel as simple as sending a text message. Yet behind our app and website lies a complex, one-of-a-kind engine of currencies and routes that’s being designed, built and powered by our talented teams in cities around the world. With new capabilities being built every day, there’s still a lot to figure out, and we can’t do it alone. This role is a unique opportunity to have an impact on Wise’s mission, grow as a product leader and help save millions more people money.  

The Security Operations Team is responsible for technical security concerns, security incident response lifecycle and AppSec across the company. We work together with product teams to minimise the amount of vulnerabilities introduced into wise products and we act as the first line of defence for attacks aimed against us internally or externally. 

Here’s how you’ll be contributing to the Engineering Team:

  • Help us detect, analyse and mitigate attacks or abuses across the company. You’ll be acting as a 2nd line Security Engineer in SOC.
  • You will be improving and developing Wise security monitoring solutions and helping relevant teams to solve problematic vectors. 
  • Together with Engineering and Platform teams you will find new ways to keep our customers and Wise safe from malicious intent while staying invisible for good customers.

Is this you?

  • Are passionate about Cybersecurity and Incident Response;
  • Have worked within a production environment and understand the importance of CI;
  • You’re passionate about defending web attacks and abuse;
  • You like to deal with complicated security incidents;
  • Are passionate about working with data - extracting information from large sets of data and finding patterns or abnormal activity;
  • Have automated your detections and mitigations in Python/Go/Java;
  • You have worked with different SIEM-s and understand what happens under the hood;
  • Know how to secure infrastructure in AWS and have done this before;
  • A good understanding of Linux and understand how to secure it;
  • You understand the value of WAF and how to maintain it;
  • An understanding of what it takes to secure Docker and Kubernetes;
  • Experience in securing networks or hardening OS;
  • Previously working experience with vulnerability scanning solutions and understanding the difference;
  • Knowledge of security standards (PCI DSS, ISO, SOC)
  • A good understanding of identity and access management and experience implementing least privilege with RBAC policies
  • On-call on a rotation basis isn't new to you and work at night if needed, but would prefer to automate the workflow;

Some extra skills that would be great:

  • Infrastructure pentesting experience;
  • Knowledge of apparmor, seccomp, eBPF
  • Experience working with IDS solutions;
  • Have an understanding of the concept of microservice architectures;
  • A  basic understanding of statistics and Machine Learning;
  • You understand what a runbook is and can define it for simple IR purposes;
  • A good understanding of Windows internals and can work with Powershell;

What you get back:

  • 🚀 Stock options in a growing company 
  • 💪 An annual self-development budget
  • 🐶 Pet friendly offices 
  •  🏃‍♀️Lots of fun group activities like yoga, running and boardgame nights 
  • 🌍 Relocation and visa expenses covered 
  • 🏝️ A paid 6-week sabbatical leave after four years 

Find out more about our benefits in our Tallinn office.

Interested? Find out more:

...or check out our Engineering blog.

We’re people without borders — without judgement or prejudice, too. We want to work with the best people, no matter their background. So if you’re passionate about learning new things and keen to join our mission, you’ll fit right in.

Also, qualifications aren’t that important to us. If you’ve got great experience, and you’re great at articulating your thinking, we’d like to hear from you.

And because we believe that diverse teams build better products, we’d especially love to hear from you if you’re from an under-represented demographic.

#LI-KH2

Tags: Application security AWS Banking Docker IDS Incident response Java Kubernetes Linux Machine Learning Monitoring PCI DSS Pentesting PowerShell Python SIEM Vulnerabilities Windows

Perks/benefits: Career development Equity Paid sabbatical Pet friendly Team events Yoga

Region: Europe
Country: Estonia
Job stats:  19  1  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.